Shadow AI hunting does not start with employees pasting data into ChatGPT.
That is where most security teams start, which is not a bad instinct, just an easy one. Consumer chatbot use is visible, the services are known, and blocking unauthorized traffic is easily solved.
Spend more time thinking about the AI tooling used by engineering and data teams.
These teams connect tools to source code, CI/CD pipelines, cloud environments, databases, APIs, and production systems. Some tools have no separate account in the corporate identity provider. Others operate through credentials assigned to a human user.
A security team can monitor every visit to ChatGPT and still miss the activity that creates the greatest Shadow AI security risk: AI tooling with access to production.
For more on agentic architecture and non-human identity, our guide on AI Agents vs. Agentic Systems in Security Operations covers the underlying concepts.
Why the Shadow AI Conversation Starts in the Wrong Place
Ask security teams about Shadow AI, and most will talk about user input. They want to know whether employees are pasting customer records into ChatGPT or uploading confidential documents to public models.
This fear is common. According to a study by Gartner, 69% of companies suspect that their employees are using unauthorized public GenAI technology. However, focusing on public tools can pull attention toward the activity that is easiest to spot.
Detection from the engineering team’s side is harder. A developer integrates a coding tool with a repository, or a data scientist calls an external model within an analytics flow. A development team might integrate an AI service into an application via an API without creating a new SaaS account that can be easily detected by security.
Look there before assuming browser activity says much about your organization’s real exposure.
Most people adopt these tools with good intent. The risk depends heavily on the access surrounding the tool. An AI service that helps rewrite an email presents one set of concerns. A tool connected to systems that build and deploy software presents another.
Where Shadow AI Actually Surfaces First
Engineering teams work with repositories, build systems, deployment pipelines, cloud infrastructure, secrets, and production applications. Data teams may work with customer records, proprietary business data, analytics environments, and production data stores.
When either team adds AI to an existing workflow, the tool can gain access to sensitive systems, expanding the AI attack surface.
Analysts need to establish what it can read, what it can change, which credentials support it, and what other systems trust those credentials. A low-privilege experiment against synthetic data deserves a different response from an unsanctioned service connected to production code.
We would prioritize according to blast radius. Understanding that blast radius is what allows real risk-based decisions.
Why It Spreads Faster and Hides Better Than Traditional Shadow IT
There is a distinction between Shadow IT and Shadow AI. Traditional Shadow IT often leaves something concrete behind: an application, cloud service, account, network connection, or expense.
Sometimes, Shadow AI is already embedded in your workflows. A developer connects a third-party model to an approved application through an API, or adds AI capabilities to engineering tools already in use. The tool may then operate with an employee token or existing service credential.
Nothing has to appear as a new AI account in Okta or Google Workspace.
Security operations centers (SOCs) may see legitimate credentials interacting with legitimate systems and have no obvious indication that an unsanctioned AI tool sits between the person and the action.
Experiments can also become permanent before governance catches up. By the time security finds the tool, colleagues may already depend on it.
The Visibility Gap: Why “We Monitor ChatGPT” Isn’t an Answer
Browser monitoring shows which AI services users access through channels that are monitored. It does not show every model called through an API, all AI components inside an engineering pipeline, or each tool operating through an existing credential.
Often, telemetry is the first limitation.
If you do not gather relevant identity events, API activity, repository changes, credential use, pipeline behavior, and cloud actions, you will be unable to piece this activity together later. There is no detection solution that can recover data that was never collected.
It becomes even more difficult when this activity is carried out under a legitimate identity. A known user, valid token, and expected permissions can still give an analyst the wrong impression about who, or what, performed an action.
What’s Actually at Risk: Source Code, Pipelines, and Credentials
Within engineering environments, pay particular attention to source code, credentials, and CI/CD pipeline security.
Source repositories hold the company's intellectual property and operational knowledge. Pipelines link development and deployment. The credentials used for these processes could grant access beyond the system where the investigation starts.
The time available to investigate that access is also shrinking. Recent threat research recorded the fastest lateral movement at four minutes, the fastest data exfiltration at six minutes, and an average breakout time of 34 minutes.
An AI tool connected anywhere in that chain may influence more than its immediate task.
Data teams face a similar issue. A third-party AI service connected to an analytics environment or production data store may gain sensitive access without creating the visible footprint security teams expect from Shadow IT.
The practical question is how far an action can travel if the tool, credential, or workflow behaves unexpectedly.
The Identity Problem Underneath It All
Consider a user called Bob.
Your logs show Bob modifying code, calling an API, or interacting with a production system. Bob may have performed the action himself. An unsanctioned AI tool may also have performed it using Bob’s credentials or through a workflow he initiated.
The identity record cannot settle that question, which is one of the trickiest problems in AI identity management.
The AI tool may never receive its own account. Bob is still the authenticated identity even when software makes decisions and takes actions on his behalf.
This is becoming an increasingly important identity issue as AI systems become more autonomous. The National Institute of Standards and Technology (NIST) has advocated for adaptive identity and access controls that account for the growing role of non-human identities.
Security teams cannot work without behavioral context. Sudden changes in repository activity, API sequences, credential use, access timing, or velocity may warrant investigation.
With GreyMatter, we correlate activity from current security solutions and environments, enabling analysts to view identity activity alongside other telemetry and potentially gain insight into permissions, behavioral context, and blast radius without having to reconstruct activity across disconnected console environments.
Security teams also need to know who has the means to influence, push, or chain together internal systems built on top of AI.
Inside GreyMatter, Agentic Teammates inherit the permissions of the user who initiated the request. In other words, if the user cannot access a resource or perform an action, neither can the agent.
Building Detection from Scratch: The First Three Signals
We recommend starting with:
Behavioral baselines. Monitor significant shifts in velocity, time, access patterns, and behaviors of identities who have the ability to change code, pipelines, production systems, or sensitive data.
Credential vaults and approved tooling. Monitor the credentials used by approved tools to connect to important systems, which may indicate compromise of the visibility layer itself.
Error-handling and retry behavior. Look out for processes that interpret errors, tweak inputs, select a different tool, or try an alternate path to achieve the same goal.
The third signal deserves attention. Scripted automation tends to fail according to predefined logic. AI-driven activity can adjust after failure.
Do not treat that pattern as proof of AI; use it to identify activity that warrants closer investigation.
Response Without Becoming the Department of No
We do not believe security teams can prohibit their way out of Shadow AI.
Most employees who introduce these tools are just trying to get their work done. If every new AI use case meets an automatic block, engineering and data teams will continue experimenting without involving security. The organization loses the cooperation it needs to understand access and risk.
The RACI needs to be explicit about who can authorize an AI application, who evaluates access to the application, who takes responsibility for the risks produced by the application, who observes behavior, and who intervenes in case of an anomaly.
Shadow AI does not fall under any particular function; security, engineering, IT, compliance, and data management functions may all play some role. The problem is when each thinks the other will handle the issue.
Closing perspective: Shared Ownership is a Challenge
Shadow AI reveals that several teams may own parts of the problem without clear boundaries between them.
Consumer chatbot monitoring still has value, but it does not tell you which AI tools can modify source code, use trusted credentials, influence deployment pipelines, or connect to production data.
The CISO must understand who has approval authority to introduce an AI application into production, who changes the AI application's guardrails, and who is responsible for investigating activity performed by a legitimate identity that does not fit the user.
If these questions hinge on assumptions, risk decisions become a guessing game. CISOs need evidence of who can influence these systems and how far that influence can travel, rather than relying on what they have been told.
Request a GreyMatter demo to see how identity and behavioral context can support security investigations across your environment.

